<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TPRM fiasco in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/TPRM-fiasco/m-p/17821#M792</link>
    <description>&lt;P&gt;Good day all!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the situation - a third party that has been providing services for many years has revealed (during a review) that they do not provide encryption services (as per the customer requirements) as it's not viable for them financially. At the onset&amp;nbsp; of the business relationship this was not the practice and it was ignored for some years and over time due to some regulations it has come up with high priority.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third party service provider not ready to provide the required service&lt;/P&gt;&lt;P&gt;Moving to another service provider will incur huge cost&amp;nbsp; to the org&lt;/P&gt;&lt;P&gt;Encryption service is necessary for the compliance otherwise a huge fines and great danger to the business&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the best course of action?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jan 2019 09:00:20 GMT</pubDate>
    <dc:creator>iluom</dc:creator>
    <dc:date>2019-01-11T09:00:20Z</dc:date>
    <item>
      <title>TPRM fiasco</title>
      <link>https://community.isc2.org/t5/Tech-Talk/TPRM-fiasco/m-p/17821#M792</link>
      <description>&lt;P&gt;Good day all!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the situation - a third party that has been providing services for many years has revealed (during a review) that they do not provide encryption services (as per the customer requirements) as it's not viable for them financially. At the onset&amp;nbsp; of the business relationship this was not the practice and it was ignored for some years and over time due to some regulations it has come up with high priority.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third party service provider not ready to provide the required service&lt;/P&gt;&lt;P&gt;Moving to another service provider will incur huge cost&amp;nbsp; to the org&lt;/P&gt;&lt;P&gt;Encryption service is necessary for the compliance otherwise a huge fines and great danger to the business&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the best course of action?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 09:00:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/TPRM-fiasco/m-p/17821#M792</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-01-11T09:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: TPRM fiasco</title>
      <link>https://community.isc2.org/t5/Tech-Talk/TPRM-fiasco/m-p/17831#M794</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/637665353"&gt;@iluom&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Good day all!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the situation - a third party that has been providing services for many years has revealed (during a review) that they do not provide encryption services (as per the customer requirements) as it's not viable for them financially. At the onset&amp;nbsp; of the business relationship this was not the practice and it was ignored for some years and over time due to some regulations it has come up with high priority.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third party service provider not ready to provide the required service&lt;/P&gt;&lt;P&gt;Moving to another service provider will incur huge cost&amp;nbsp; to the org&lt;/P&gt;&lt;P&gt;Encryption service is necessary for the compliance otherwise a huge fines and great danger to the business&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the best course of action?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Document each course of action. Then do simple math to attempt to figure out best course of action.&lt;/P&gt;&lt;P&gt;Option 1) Do nothing. Yes this is always an option that most people forget about. Risk = Huge fines, breach of data, damage to corporate reputation, etc.&lt;/P&gt;&lt;P&gt;Option 2) Fire the current 3rd party and replace with new. Document the replacement cost vs current cost + fines&lt;/P&gt;&lt;P&gt;Option 3) Pay current vendor to remedy situation. Figure out cost to "upgrade" the service. Compare against costs of option #1.&lt;/P&gt;&lt;P&gt;Option 4) Can the service be brought in house? Figure out the costs and compare against all other options.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 15:58:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/TPRM-fiasco/m-p/17831#M794</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2019-01-11T15:58:50Z</dc:date>
    </item>
  </channel>
</rss>

